Threat Actors Sell Stolen Starbucks Customer Data on Hacker Forums
Key Takeaways A threat actor is allegedly selling a database containing 176 million Starbucks customer records on a cybercrime forum. The purported data includes personal details, loyalty program...
Key Takeaways
- A threat actor is allegedly selling a database containing 176 million Starbucks customer records on a cybercrime forum.
- The purported data includes personal details, loyalty program information, and password hashes, posing significant privacy and fraud risks.
- Starbucks has not confirmed the incident, and the authenticity of the data remains unverified.
- Customers are advised to monitor accounts, use unique strong passwords, and be wary of phishing attempts.
A significant cache of Starbucks customer data, purportedly totaling 176 million unique user records, is being offered for sale on a prominent cybercrime forum. The seller, operating under the alias “anes2010,” claims the database was extracted in June 2026 and includes a wide array of sensitive information.
Table Of Content
As of this report, Starbucks has not issued any public statement acknowledging or confirming the alleged security breach. Consequently, the claims made by the threat actor, including the legitimacy of the breach and the contents of the dataset, remain unverified and should be regarded as unconfirmed.
The alleged Starbucks database is listed for $400, with the threat actor reportedly providing sample records to substantiate the sale. While the sharing of samples is a common tactic employed by cybercriminals to lend credibility to their claims, these samples alone do not definitively prove the authenticity, currency, or direct origin of the entire dataset from the named organization.
According to a post shared by the threat intelligence account Intel and Breaches, the forum listing details that the alleged database encompasses email addresses, usernames, hashed passwords, geographical data (country and city), account creation dates, last activity timestamps, account status, and email verification status.
Alleged Starbucks Database Leak Details
The threat actor further asserts that the database contains highly sensitive information related to Starbucks Card details, including balances, auto-reload settings, preferred store locations, and beverage preferences. Additional alleged data points include customer birthdays, Starbucks Rewards points, lifetime Stars accumulated, total spending figures, and currency information.
Should these claims prove accurate, the amalgamation of account, loyalty program, and personal identifying information could expose affected customers to substantial privacy violations and elevated risks of financial fraud.
The presence of password hashes in the alleged dataset does not automatically imply plaintext password exposure. The actual risk level is contingent upon several critical factors: the specific password-hashing algorithm employed, its configuration, the use of unique salts for each hash, and the overall security controls implemented by Starbucks. Outdated or weak hashing mechanisms could potentially allow attackers to perform offline password cracking attempts, while the combination of email addresses and detailed loyalty program data could facilitate highly sophisticated and targeted phishing campaigns.
Attackers could leverage this information to craft convincing fraudulent communications regarding reward points, account suspensions, Starbucks Card balances, payment updates, changes to auto-reload settings, or account verification requests. The ultimate goal of such campaigns would be to trick recipients into divulging their credentials or payment information.
Customers who practice password reuse across multiple online services face an amplified risk. If the alleged records are validated and password hashes are subsequently compromised or cracked, these reused credentials could be exploited in “credential stuffing” attacks, where attackers attempt to use the stolen username-and-password combinations against other email, banking, retail, and social media accounts.
What You Should Do
- Monitor Account Activity: Regularly check your Starbucks Card balance, rewards activity, stored payment methods, and account profile for any unauthorized or suspicious changes.
- Be Wary of Phishing: Exercise extreme caution with unexpected emails, SMS messages, or calls claiming to be from Starbucks, especially those that demand urgent action.
- Avoid Suspicious Links: Do not click on links embedded in unsolicited messages. Instead, access your Starbucks account directly via the official Starbucks mobile app or by typing the company’s official website URL into your browser.
- Use Strong, Unique Passwords: Create a unique, complex password for your Starbucks account that is not reused on any other online service. Consider using a reputable password manager.
- Enable Multi-Factor Authentication (MFA): If available, enable multi-factor authentication on your Starbucks account for an added layer of security.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.